Техническая информация
- <SYSTEM32>\cmd.exe
- %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\jD8hIi9FwL.lnk
- %APPDATA%\Roaming\97C09787-6498-4B10-8F65-9471D842C55E\run.dat
- %APPDATA%\Roaming\F2t6bIXtKR\6485.xml
- %APPDATA%\Roaming\F2t6bIXtKR\6485.xml в %APPDATA%\Roaming\F2t6bIXtKR\LzHJklNNL94g.exe
- DNS ASK dn#.##ftncsi.com
- DNS ASK fe######a77.crabdance.com
- ClassName: 'Shell_TrayWnd' WindowName: ''